ZeroHour

CVE-2016-0189

KEV ransomware PoC mass

Memory Corruption RCE in Microsoft IE Scripting Engines (JScript/VBScript)

CISA: Microsoft Internet Explorer Memory Corruption Vulnerability

CVSS 3.1
7.5 high
EPSS
94%p100
Published
()
KEV added
AI analysis

CVE-2016-0189 is a memory corruption flaw (out-of-bounds write, per CWE-787) in Microsoft's JScript 5.8 and VBScript 5.7/5.8 scripting engines, as used in Internet Explorer 9 through 11 and other products that embed those engines. It is triggered remotely when a user is lured into viewing a crafted website that mishandles script, corrupting memory in the browser process. A successful attacker gains arbitrary code execution in the context of the current user (or can crash the browser, causing denial of service), with no authentication required but user interaction needed. Anyone running Internet Explorer 9-11 on Windows, or other products using the affected scripting engines, was exposed. Exploitation is well established: public write-ups document its use in drive-by exploit kit attacks and subsequent 'God Mode' local privilege-escalation variants, it is listed in CISA KEV (added 2022-03-28) with known ransomware use, and EPSS assigns a 94.1% probability of exploitation within 30 days.

What to do: Apply the vendor-supplied Microsoft security updates for Internet Explorer and the JScript/VBScript scripting engines per CISA's required action, prioritizing endpoints used for web browsing and email since this is delivered via drive-by website attacks and is known to be used by ransomware operators. Systems that no longer receive updates for IE 9-11 should be migrated to a supported browser or OS. Check your environment against CISA KEV to confirm remediation status.

Affected
microsoft Internet Explorer9 through 11
microsoft JScript scripting engine5.8 (as used in Internet Explorer 9-11 and other products)
microsoft VBScript scripting engine5.7 and 5.8 (as used in Internet Explorer 9-11 and other products)
Estimated exposure
masshundreds of millions of Windows endpoints at disclosure (IE 9-11 shipped as the default Windows browser); residual exposure on legacy/enterprise Windows… — Internet Explorer 9-11 was the default browser component on Windows 7/8.1/10 and the JScript/VBScript engines ship with Windows itself, giving IE roughly a third of desktop browser market share in 2016, so exposure is estimated from that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
jscript, vbscript, internet explorer
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news